Bug 2228392 (CVE-2023-31486) - CVE-2023-31486 http-tiny: insecure TLS cert default
Summary: CVE-2023-31486 http-tiny: insecure TLS cert default
Keywords:
Status: NEW
Alias: CVE-2023-31486
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2228396 2228397 2228398 2228409 2228410 2228411 2228412 2228395
Blocks: 2192430
TreeView+ depends on / blocked
 
Reported: 2023-08-02 10:20 UTC by TEJ RATHI
Modified: 2023-08-02 13:38 UTC (History)
16 users (show)

Fixed In Version: HTTP-Tiny 0.083-TRIAL
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2023-08-02 10:20:32 UTC
HTTP::Tiny v0.082, is a http client included in Perl (since v5.13.9) and also a standalone CPAN module. It does not verify TLS certificates by default requiring users to opt-in with the verify_SSL=>1 flag to verify the identity of the HTTPS server they are communicating with.

https://www.openwall.com/lists/oss-security/2023/04/18/14
https://github.com/chansen/p5-http-tiny/issues/134
https://github.com/chansen/p5-http-tiny/pull/153
https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/
https://hackeriet.github.io/cpan-http-tiny-overview/
https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/
https://github.com/advisories/GHSA-g56r-phrf-6pc4

Comment 1 TEJ RATHI 2023-08-02 10:24:53 UTC
Created perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228395]


Created perl:5.32/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228396]


Created perl:5.34/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228397]


Created perl:5.36/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228398]


Note You need to log in before you can comment on or make changes to this bug.